Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0438

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0439

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6425

Published Jan 23, 2008

Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0394

Published Jan 23, 2008

Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0395

Published Jan 23, 2008

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0396

Published Jan 23, 2008

Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0397

Published Jan 23, 2008

Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0398

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0399

Published Jan 23, 2008

Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long argument…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0400

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the galle…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0402

Published Jan 23, 2008

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictio…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0403

Published Jan 23, 2008

The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0404

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0392

Published Jan 23, 2008

Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) Conne…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0393

Published Jan 23, 2008

Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla par…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0128

Published Jan 23, 2008

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https sessio…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-0388

Published Jan 23, 2008

SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0389

Published Jan 23, 2008

Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0391

Published Jan 23, 2008

inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conj…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0065

Published Jan 22, 2008

Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,251-5,275 of 5,632 CVEsPage 211 of 226